Research is the last sector in Annex 2 to OUG 155/2024. Medium-sized and large organisations are important entities, with standard scores of 125 and 187.5, so the important level. The definition is restrictive, though: what matters is the purpose of the research, not just the fact that you do research.
Who is covered by NIS2 in research
Annex 2 to OUG 155/2024 takes over the list and definition in the NIS2 Directive. What counts is the entity’s primary goal. In practice, it covers:
- research and development institutes and centres, if their primary goal is applied research or experimental development with a view to commercial exploitation of the results;
- R&D companies: private laboratories and engineering and product development companies working under contract;
- not covered: education institutions, including universities, even if they do research.
Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.
Which assurance level applies
| Organisation size | Entity type | Standard risk score | Assurance level | At self-assessment |
|---|---|---|---|---|
| Small or micro | outside NIS2, except for the cases in the law | 62.5 | basic | 34 controls, threshold 2.5 |
| Medium | important | 125 | important | 133 controls, threshold 3 |
| Large | important | 187.5 | important | 133 controls, threshold 3 |
The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.
Find your level and maturity score in a few minutes. The calculator opens with the “Research” sector already selected; you choose the size and answer 12 questions.
Calculate the level for researchWhich systems are assessed in a research organisation
In a research organisation, the value lies in data and results. The assessment usually covers:
- computing infrastructure: clusters, compute servers and research data storage;
- connected laboratory equipment, often running old operating systems;
- collaboration platforms with external partners and their accounts;
- project documentation, results and patent applications;
- administrative systems: projects, procurement, human resources;
- remote access by researchers and partners.
Europe’s supercomputers, May 2020
In May 2020, several high-performance computing centres in Europe were taken offline after intrusions: ARCHER, at the University of Edinburgh, several clusters in Germany, including at the Jülich Research Centre, and the Swiss centre CSCS. The attackers installed cryptocurrency miners, and the German centres reset users’ SSH passwords.
Research has a different risk profile from other sectors: many external users, international collaborations, old laboratory equipment and data that is valuable for industrial espionage. Often the goal is not to stop the work but to use the resources or steal the results.
For NIS2, this shifts the focus to identities and data: personal accounts for every collaborator, multi-factor authentication for remote access, accounts closed at the end of projects and classification of project data, so that you know what needs better protection.
What comes next
- notification to DNSC, within 30 days from the date OUG 155/2024 becomes applicable to the organisation; the first DNSC fine sanctioned exactly this deadline;
- the risk-level assessment, within 60 days of the DNSC decision;
- the self-assessment, within the following 60 days, on the controls of your level;
- the audit, carried out by a DNSC-certified auditor.
How TRU helps
In research, protecting results matters as much as availability. We start with:
- PenTest, external, on remote access and collaboration platforms, with reports within 48 hours of the scan being completed;
- Proton Workspace, for project documentation and data exchange with partners, with zero-access encryption, the encryption keys under your control and physical security key authentication;
- SOC 24/7/365, to detect unusual access to data and to collaborators’ accounts.
Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.
Frequently asked questions
Is a university covered by NIS2?
Not as a research organisation: the definition excludes education institutions, even if they do research.
We have an R&D department. Are we covered under research?
As a rule, no: what counts is the entity’s primary goal. A factory with an R&D department is classified by its main activity, for example under manufacturing.
We do basic research with no commercial aim. Are we covered?
Not on this basis. The definition targets applied research and experimental development with a view to commercial exploitation of the results.
Sources
OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · Security Affairs, supercomputers hacked across Europe, 17 May 2020.